Privacy Policy
Effective date: August 26, 2026
Rolling Mango Corp (the "Company") protects your privacy under a principle of minimal collection. This policy explains what the App "Purrhaps" collects and how it is processed.
1. Information We Collect
- Nickname, birthday, and cat's name: entered by you and stored on your device (local storage). The free daily fortune is computed from your birthday on-device, and while you use the App anonymously this information is not sent to the server. ("Profile account sync" and "Premium Saju information" below are exceptions.)
- Profile account sync (stored on the server when signed in): if you sign in with Apple or Google, your profile (nickname, date of birth, time of birth, gender, cat's name) is stored on the server (Supabase) linked to your account identifier, so that you can carry your profile over after changing devices or reinstalling. While you use the App anonymously, your profile stays on your device only. Notification on/off, notification time, and onboarding completion are per-device settings and are not stored on the server.
- App settings (e.g., notification on/off, notification time): stored only on your device.
- Login account information (optional): if you choose to sign in with Apple or Google, the email address and account identifier provided by the login provider are stored on the authentication server (Supabase). Sign-in is optional; without it you can use the App with an anonymous session.
- Server-stored data: your daily fortune history and your Churu / Can balances and transaction records are stored on the server (Supabase) linked to your (anonymous or logged-in) account identifier.
- Premium Saju information (stored on the server): when you open a premium Saju reading — whether by spending Cans or through a limited-time free promotion — the date of birth, time of birth, and gender used to produce that reading are stored on the server (Supabase) together with the entitlement, linked to your account identifier. This is so you can reopen it from your library and restore it after changing devices or reinstalling. In other words, using a premium Saju reading stores your birth information on the server regardless of whether you paid.
- Other people's Saju information: if you choose to create or open a reading for someone other than yourself, that person's name, date of birth, time of birth, and gender are entered and stored on the server in the same way. You must obtain lawful consent or authority from that person before entering their information.
- Advertising identifier: to serve rewarded ads, your device advertising identifier may be processed by Google AdMob. In addition, your Android Advertising ID is processed by Google to attribute app installs to advertising and to measure ad performance. On iOS the advertising identifier (IDFA) is not collected. In no case does the Company perform cross-app or cross-web tracking or serve personalized ads.
- App usage records: to improve the service and measure ad performance, in-app usage records (onboarding completion, opening and sharing fortune cards, completing a rewarded ad, opening the shop, and whether a purchase completed) along with app version, device model, operating system, country and language are collected through Google Analytics for Firebase. These records do not include profile information such as birth date, name, gender or birth hour, nor any account identifier.
- Purchase verification data: for paid purchases, receipts and transaction identifiers issued by the app stores (Apple / Google) are used to verify purchases. The Company does not collect or store payment method details such as card numbers.
2. How We Use Information
- Computing personalized fortunes and premium Saju readings based on your birth information
- Delivering fortune reminders
- Saving, displaying, and reopening received fortunes, Churu / Can balances, and premium Saju entitlements
- Restoring and syncing your data via account linking when you sign in
- Granting rewarded-ad rewards and verifying paid purchases (including abuse prevention)
- Analyzing usage statistics for service improvement and measuring ad performance
3. Retention and Deletion
Nickname, birthday, cat's name, and app settings are stored on your device and removed when you delete the App.
Your fortune history, Churu / Can balances and transaction records, and premium Saju entitlements together with the birth information they contain (date of birth, time of birth, gender) are stored on the server linked to your account identifier. In an anonymous state without sign-in, deleting the App ends the anonymous session, so your balances (including purchased Cans and the Churu exchanged or earned from them) and Saju entitlements may not be restored upon reinstalling. If you sign in with Apple or Google, your data is linked to your account and can be restored after changing devices or reinstalling.
If you request account deletion — in the App under Settings → Account → Delete account, or via the contact below — the server data linked to that account (fortune history, balances, transaction records, premium Saju entitlements and the birth information they contain) is deleted along with it. Deletion is held for a 30-day grace period during which you can cancel it in the App and restore your data. After 30 days the server data is permanently deleted and cannot be recovered. See Account & Data Deletion for the procedure.
4. Processors and Third Parties
- Supabase: server infrastructure used for anonymous and social-login authentication, storing and serving profile / fortune / currency / Saju entitlement data, in-app purchase receipt verification, and ad-reward server verification.
- Social login (optional): if you choose to sign in, Apple (Sign in with Apple) or Google handles authentication and provides your email and account identifier.
- Apple App Store · Google Play: handle in-app purchase processing and receipt issuance for paid Can packs. Payment method details (such as card numbers) are handled by each store; the Company does not collect or store them.
- Google AdMob: processes advertising identifiers under its own policies to serve rewarded ads. The Company operates with non-personalized ads.
- Google Analytics for Firebase: processes app usage records and the Android Advertising ID under its own policies for usage analytics and ad performance measurement. The Company does not use this information for personalized advertising.
5. Transfer of Personal Data Overseas
The Company transfers personal data overseas as set out below in order to provide the Service. You may refuse the transfer, but if you do, features that require server storage (sign-in, profile sync, the premium Saju library, balance restoration, and rewarded ads) will be unavailable.
- Supabase Inc. (United States) — Country of transfer: Japan (data center region ap-northeast-1, Tokyo) / Items: account identifier and email, profile (nickname, date of birth, time of birth, gender, cat's name), fortune history, currency balances and transaction records, premium Saju entitlements and the birth information they contain / Purpose: authentication, data storage and delivery / Retention: until the 30-day grace period after account deletion has elapsed
- Google LLC (United States) — Items: advertising identifier and other data needed to serve ads; app usage records and the Android Advertising ID; email and account identifier when using social login / Purpose: serving rewarded ads, usage analytics and ad performance measurement, login authentication, in-app purchase processing / Retention: per that company's policy
- Apple Inc. (United States) — Items: email (including Private Email Relay) and account identifier when using social login; in-app purchase receipts and transaction identifiers / Purpose: login authentication, in-app purchase processing / Retention: per that company's policy
6. Advertising Identifiers
Advertising identifiers may be used to serve rewarded ads and to measure ad performance. On Android, the Advertising ID is used to attribute app installs to advertising; on iOS the advertising identifier is not collected. In no case does the Company perform cross-app or cross-web tracking or serve personalized ads.
- iOS: You can adjust ad-related settings under Settings → Privacy & Security.
- Android: You can reset or delete your Advertising ID under Settings → Privacy → Ads.
7. Children's Privacy
The App is intended for users aged 14 and over. It is not primarily directed to children under 14, and we do not knowingly collect their personal information.
8. Your Rights
You can edit your nickname, birthday, and cat's name directly in the App, or delete all local data by removing the App. You may also request account deletion (deletion of server-side data) in the App under Settings → Account → Delete account, or via the contact below. Within 30 days of the request you can cancel it in the App and restore your data.
You may request access to, correction of, deletion of, or suspension of the processing of your personal data. If you are dissatisfied with how the Company handles such a request, you may seek mediation or advice from the Personal Information Dispute Mediation Committee (+82-1833-6972), the Privacy Infringement Report Center (118), the Supreme Prosecutors' Office (1301), or the National Police Agency (182).
9. Privacy Officer
The Company has designated a privacy officer who is responsible for personal data processing and for handling user inquiries, complaints, and remedies.
- Privacy Officer: Park Junghoon (CEO)
- Contact: info@rollingmango.co.kr
10. Contact
For privacy inquiries: info@rollingmango.co.kr
11. Changes to This Policy
If this policy changes, we will notify you via an app update or this page.